-
Notifications
You must be signed in to change notification settings - Fork 14
Open
Description
A non-DELEG-aware ("legacy") validating stub can only use records that carry a non-DELEG DNSSEC signature chain. This seems to be incompatible with the "sharedds" mechanism proposed in the DNSSEC draft.
It's also unclear how to construct a DELEG-aware validating stub, as DELEG records are not presently passed to the stub at all.
At present, I think the result is that any query to a recursive resolver with DO=1 would require the resolver to skip any DELEG records with "sharedds", and would create some very complicated caching questions. This seems like bad news for "sharedds".
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels